Privacy Policy
Effective Jul 28, 2026
What we collect
- The URL you submit and the results of scanning it (findings, severities, and the generated report).
- Your email: optional for a free scan; required for an account.
- Your acceptance of our terms: when you accept them on a scan, we store the terms version, a timestamp, and the IP address you accepted from.
- Account identifiers for signed-in users (managed by Amazon Cognito).
- Billing metadata from our payment processor (such as your customer and subscription identifiers). We never receive or store your raw card details.
- Branding assets, on an Agency plan: the brand name, accent color, and logo you upload. Your logo is stored in public-read storage because it is displayed on the client-facing reports and badges you generate; don't upload anything you wouldn't want served publicly.
- Client-authorization attestations, on an Agency plan: when you attest that you're authorized to actively test a client's domain, we record the clause version you accepted, who attested, a timestamp, and the IP address.
- Minimal operational logs needed to run and secure the Service.
What we deliberately don't store
If a scan discovers a secret (an API key, token, or similar), we never store or log it in readable form, it is redacted or hashed before anything is written down. We never store raw payment-card data; card details are handled entirely by our payment processor.
How we use it
- to run your scans and deliver your reports;
- if you give us your email, to send your report and occasional follow-up security guidance (you can unsubscribe at any time);
- to operate accounts, subscriptions, and billing;
- to keep the Service secure and prevent abuse;
- to maintain and improve how the Service works.
Who we share it with
We don't sell your data. We share it only with the service providers we need to run the product:
- Amazon Web Services: hosting, storage, and infrastructure.
- Amazon Cognito: account sign-in.
- Anthropic: we send scan findings (with secrets already redacted) to generate the plain-language fix guidance in your report. For paid active scans, our AI agent may also send portions of the pages and responses it retrieves from your verified site so it can analyze them; we strip recognizable secrets before sending, but that content is not otherwise filtered.
- Kit (ConvertKit): if you give us your email to receive a report, we share your email and basic scan context (the site you scanned, the top finding, and a link to your report) so we can send you the report and follow-up guidance.
- Google (Ads conversion tracking): if you arrive from a Google Ads campaign, we report back that a conversion happened (for example, a scan completed or a signup finished) so the campaign can be measured. We never send Google your email or the site you scanned, only that the conversion occurred.
- Microsoft (Clarity): on our marketing pages, Clarity records session replay, mouse movement, clicks, and scroll depth so we can see how the site is used. It does not run on your scan report, dashboard, verification, or welcome pages.
We may also disclose information if required by law, or to protect the rights, safety, and security of the Service and its users.
Retention
We keep data only as long as needed. Free-scan results are short-lived and expire automatically. If you give us your email to receive a report, we keep it (and the list of sites you scanned) until you ask us to delete it. Account and billing records are kept while your account is active and for as long as we're required to retain them afterward. We also keep anonymous, aggregate counters (such as how many sites we've scanned) indefinitely; these hold no personal data.
Cookies
To keep you signed in, we store your session token in your browser's local storage rather than in a cookie. If you arrive from a Google Ads campaign, Google's tracking script sets its own advertising cookies and reads the ad-click identifier attached to the link you clicked, so we (and Google) can tell which ad led to a scan or signup. That script loads only on pages a Google Ads visitor can land on or convert through, not across the whole Service. On our marketing pages, Microsoft Clarity sets its own cookies (_clck and _clsk) to recognize repeat visits and stitch together a browsing session. When we test two versions of a page against each other, we set our own cookies to keep the version you see consistent and to measure which one performs better. These are named ab_<test>, ab_props, and ab_x_<test>; they hold a random visitor id plus which version of the page you were shown, last 30 days, and are first-party cookies that never leave this site.
Analytics
We use Plausible Analytics to understand aggregate traffic and how the scan funnel performs. It is cookieless and collects no personal data (no cross-site tracking and no advertising profiles), so no consent banner is needed. We never send it your email or the URL you scanned. The only scan-derived value it receives is a coarse severity category (for example, “critical” or “clean”) with no link back to your site, so its events stay anonymous and aggregate.
Your choices and rights
You can request access to, correction of, or deletion of the personal data we hold about you by emailing us. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we'll honor those rights as required.
Security and data location
Data is encrypted in transit, access is least-privilege, and active scans egress from a dedicated address for traceability. The Service runs on AWS infrastructure in the United States; if you use it from elsewhere, your data is processed there.
Children
The Service isn't directed to children, and we don't knowingly collect data from anyone under 16.
Changes
We may update this policy; the effective date above will change when we do. Significant changes will be made clear on this page.
Contact
Privacy questions or requests? Email security@ismysitehackable.com. See also our Terms of Service.